CVE-2025-2894: Unitree Go1 Robot Dog Backdoor Control Channel
The Go1 also known as "The World's First Intelligence Bionic Quadruped Robot Companion of Consumer Level," contains an undocumented backdoor that can enable the manufacturer, and anyone in possession of the correct API key, complete remote control over the affected robotic device using the CloudSail remote access service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2894?
CVE-2025-2894 is considered a high-severity vulnerability due to the undocumented backdoor providing complete remote control over the Unitree Go1 robot.
How do I fix CVE-2025-2894?
To mitigate CVE-2025-2894, it is crucial to immediately disconnect the Unitree Go1 from the internet and monitor for security updates from the manufacturer.
What are the potential risks of CVE-2025-2894?
The risks associated with CVE-2025-2894 include unauthorized access, surveillance, and potential misuse of the robotic device.
Who is affected by CVE-2025-2894?
CVE-2025-2894 affects users of the Unitree Go1 robotic companion that utilize the undocumented API key for control.
When was CVE-2025-2894 discovered?
CVE-2025-2894 was discovered recently, highlighting vulnerabilities related to security in consumer robotic devices.